The Safari 27 Precedent: Why First-Party Identity Matters

Apple's Safari 27 silently blocks the third-party identity resolution ecosystem on iOS. AdFixus wasn't affected because it runs entirely on first-party, consent-based infrastructure - a privacy first internet is coming.

What Happened

In September 2026, Apple shipped Safari 27 (iOS 27) with a silent domain block that prevents The Trade Desk's ad server (adsrvr.org) from serving ads on iPhone and iPad. The block operates on a private, unpublished list of registrable domains, applied before any tracker-exemption logic in WebKit.

The same list reportedly includes domains used by Unified ID 2.0, ID5, LiveRamp, Permutive, and Audigent (Experian) — the core of the post-cookie identity resolution ecosystem.

Apple has provided no public explanation, and changes to the list will only be visible through observed behaviour.

AdFixus was not impacted. Unlike the affected providers, AdFixus is built with privacy at its core — first-party data only, consent by design, opt-out enabled, and anonymity by default.

Why This Is a Structural Risk (Not a One-Off)

  • No notice, no recourse: The list is private. Affected vendors learned via a WebKit bug report, not a deprecation notice.
  • Applies to registrable domains: Every subdomain is caught - no workaround via subdomain restructuring.
  • Pre-exemption execution: The check runs before WebKit's own tracker exemption, meaning even "whitelisted" flows can be blocked.
  • Precedent for expansion: Nothing in the mechanism limits the list to identity. It could theoretically target any third-party domain.
  • Consumer base: iOS 27 is rolling out to a massive install base. For Australian and APAC publishers, Safari/iOS represents a significant share of display inventory.

Why AdFixus Identify Is Not Affected

What Apple's Safari 27 block makes visible is a broader truth - 0identity infrastructure built on third-party domains places the consumer's data in the hands of intermediaries they never chose, on infrastructure they never consented to, controlled by platforms they have no recourse against.

AdFixus Identify was designed to invert that model:

  • First-Party enablement: Identifiers are captured only on domains where the user has a direct, first-party relationship - the site they visited. No third-party identity broker sits between the consumer and the data.
  • Consent is the entry point: AdFixus Identify operates on a consent-based deployment model. The consumer decides whether and when identification occurs - there is no silent, background resolution of a third-party identity.
  • Encryption by default: The ClientID (prid) is double-encrypted. It is a matching token, not a readable profile.

AdFixus is not impacted. This is the inevitable result of designing identity around the principle that the consumer's data should be governed by the consumer and the parties they directly engage with - not by an anonymous network of third-party resolvers that a platform vendor can disable without notice.

 Publishers and advertisers who build on this model are aligning with the direction of privacy regulation, platform enforcement, and consumer expectation. The question is no longer whether third-party identity domains will face platform-level restrictions -0 the question is which ones, and when.

‍

A new era of customer identity

Get in touch for a free audit of your identity stack.

By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.